CVE-2022-35282: SSRF
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.
Other sources
IBM WebSphere Application Server is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-35282?
CVE-2022-35282 is a vulnerability in IBM WebSphere Application Server that allows server-side request forgery (SSRF) attacks.
What is the severity of CVE-2022-35282?
CVE-2022-35282 has a severity rating of 6.5 (Medium).
How does CVE-2022-35282 affect IBM WebSphere Application Server?
CVE-2022-35282 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
How can an attacker exploit CVE-2022-35282?
An attacker with local network access can exploit CVE-2022-35282 by sending a specially crafted request to perform server-side request forgery (SSRF) attacks and obtain sensitive data.
How can I fix CVE-2022-35282?
To mitigate CVE-2022-35282, IBM recommends applying the necessary security fixes provided by IBM for affected versions of WebSphere Application Server.